zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - September 29, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - September 29, 2026

Product Serial: D-2026-09-29a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple groups posted new leak site entries, including M3RX Ransomware, Qilin Ransomware, INC Ransomware, and INTERLOCK Ransomware.
  • Unauthorized Access Marketplace: Threat actors advertised live PMS access affecting the India-based hospitality sector, a broader compromise of Indian government, ISP, and healthcare infrastructure, and alleged insider access to Anthropic, on deep and dark web (DDW) Exploit, PwnForums, and BreachForums.
  • Vulnerability and Tooling Commercialization: Threat actors advertised exploits including a working pre-auth RCE and WAF bypass for Oracle PeopleSoft, a Windows Defender update pipeline DoS, a WhatsApp Android RCE, a Chromium RCE exploit chain, and an iOS zero-day dubbed "VERMAN."
  • Data Dissemination and Telemetry: Threat actors posted several data sale claims, including alleged data tied to Bouclair, Easy Cosmetic, and Alaxione, alongside smaller processed breach data sets. Credential systems ingested over 1.57 billion combined compromised account credentials (CAC) and botnet CAC records between September 1 and September 28, 2026.

Tags: tlp:clear,  dark web,  vulnerability/exploit,  data breach,  threat actor